<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Honeypots on System Overlord</title><link>https://systemoverlord.com/tags/honeypots.html</link><description>Recent content in Honeypots on System Overlord</description><generator>Hugo</generator><language>en-us</language><managingEditor>david@systemoverlord.com (David Tomaschik)</managingEditor><webMaster>david@systemoverlord.com (David Tomaschik)</webMaster><lastBuildDate>Fri, 04 Sep 2020 00:00:00 +0000</lastBuildDate><atom:link href="https://systemoverlord.com/tags/honeypots/index.xml" rel="self" type="application/rss+xml"/><item><title>Lessons Learned from SSH Credential Honeypots</title><link>https://systemoverlord.com/2020/09/04/lessons-learned-from-ssh-credential-honeypots.html</link><pubDate>Fri, 04 Sep 2020 00:00:00 +0000</pubDate><author>david@systemoverlord.com (David Tomaschik)</author><guid>https://systemoverlord.com/2020/09/04/lessons-learned-from-ssh-credential-honeypots.html</guid><description>&lt;p&gt;For the past few months, I&amp;rsquo;ve been running a handful of SSH Honeypots on some
cloud providers, including &lt;a href="https://cloud.google.com"&gt;Google Cloud&lt;/a&gt;,
&lt;a href="https://m.do.co/c/b2cffefc9c81"&gt;DigitalOcean&lt;/a&gt;, and
&lt;a href="https://shareasale.com/r.cfm?b=1380239&amp;amp;u=2497236&amp;amp;m=46483&amp;amp;urllink=&amp;amp;afftrack="&gt;NameCheap&lt;/a&gt;.
As opposed to more complicated honeypots looking at attacker behavior, I decided
to do something simple and was only interested in where they were coming from,
what tools might be in use, and what credentials they are attempting to use to
authenticate. My dataset includes 929,554 attempted logins over a period of a
little more than 3 months.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re looking for a big surprise, I&amp;rsquo;ll go ahead and let you down easy: my
analysis hasn&amp;rsquo;t located any new botnets or clusters of attackers. But it&amp;rsquo;s been
a fascinating project nonetheless.&lt;/p&gt;</description></item></channel></rss>